Event ID 4897 is generated by the Microsoft-Windows-Security-Auditing provider when Windows detects a change to the security descriptor of a certificate template in Active Directory Certificate Services. The security descriptor defines access control lists (ACLs) that determine which users, groups, or computers can perform specific operations on certificate templates.
This event occurs on Certificate Authority servers and domain controllers when administrators modify template permissions through the Certificate Templates MMC snap-in, PowerShell commands, or direct Active Directory modifications. The event captures comprehensive details including the template name, the security principal making the change, the process involved, and timestamp information.
Certificate template security descriptors control critical PKI operations including certificate enrollment, template management, and administrative access. Changes to these permissions can affect certificate issuance policies, autoenrollment behavior, and overall PKI security posture. The event provides audit trails required for compliance frameworks like SOX, HIPAA, and PCI-DSS that mandate tracking of security-sensitive configuration changes.
In enterprise environments, this event is particularly valuable for detecting unauthorized PKI modifications, troubleshooting certificate enrollment issues, and maintaining security baselines. The event data includes sufficient detail to correlate with other security events and reconstruct the sequence of template modifications for forensic analysis.